CVE-2014-7221

MEDIUM

TeamSpeak 3 < 3.0.14 - Authenticated Denial of Service via Crafted BBCode Image Tag

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-7221.

AI-analyzed exploit summary The exploit demonstrates a buffer overflow vulnerability in TeamSpeak Client v3.0.14 and earlier versions. It provides two distinct payloads that, when sent in the chat/server tab, cause a crash due to improper handling of BBCode image tags.

Description

TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash) by connecting to a channel with a different client instance, and placing crafted data in the Chat/Server tab containing [img]//http:// substrings.

Exploits (1)

exploitdb WORKING POC
doswindows
https://www.exploit-db.com/exploits/34857

The exploit demonstrates a buffer overflow vulnerability in TeamSpeak Client v3.0.14 and earlier versions. It provides two distinct payloads that, when sent in the chat/server tab, cause a crash due to improper handling of BBCode image tags.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: TeamSpeak Client v3.0.14 and earlier
No auth needed
Prerequisites: Access to a TeamSpeak server/channel with vulnerable clients
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70219
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/96889
Broken Link x_refsource_misc
http://r4p3.net/public/ts3bbcodefreeze.txt
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://packetstormsecurity.com/files/128571/TeamSpeak-Client-3.0.14-Buffer-Overflow.html

Scores

CVSS v3 6.5
EPSS 0.1097
EPSS Percentile 95.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-119
Status published
Products (1)
teamspeak/teamspeak3 < 3.0.14
Published Jan 08, 2018
Tracked Since Feb 18, 2026